A threat intelligence analyst is updating a document according to the MITRE ATT&CK framework. The analyst detects the following behavior from a malicious actor: 'The malicious actor will attempt to achieve unauthorized access to the vulnerable system.' In which of the following phases should the analyst include the detection?
Tactics
In the MITRE ATT&CK framework, tactics represent the highest level of abstraction, outlining the general objectives that an adversary aims to achieve during an attack. The behavior described, attempting unauthorized access to a vulnerable system, aligns with a strategic goal or intent of the malicious actor. Therefore, this detection should be included in the Tactics phase to provide a broad overview of the adversary's objectives.
Procedures in the MITRE ATT&CK framework refer to specific step-by-step instructions or processes followed by threat actors to accomplish their objectives. The behavior of attempting unauthorized access is more aligned with the strategic level of Tactics rather than the detailed operational level covered by Procedures.
Techniques in the MITRE ATT&CK framework are more detailed than Tactics and represent specific methods or means used by adversaries to execute their objectives. While attempting unauthorized access is an action taken by the malicious actor, it fits better within the broader strategic context of Tactics rather than the specific operational level of Techniques.
Subtechniques are the most granular level of detail in the MITRE ATT&CK framework, describing specific variations or implementations of techniques. Since the behavior described is at a higher level of abstraction related to the adversary's goal, it does not delve into the specific variations or subcategories covered by Subtechniques.
In the context of the MITRE ATT&CK framework, the behavior of attempting unauthorized access to a vulnerable system should be categorized under Tactics. By including this detection in the Tactics phase, the threat intelligence analyst can better understand the overarching strategic objectives of the malicious actor and enhance their cybersecurity defense strategies accordingly.
Related Questions
View allAn analyst uses an AI platform to help correlate events. The AI output...
A security manager requests that an analyst generates a report of the...
An analyst is evaluating a vulnerability management dashboard. The ana...
Which of the following is the best technical method to protect sensiti...
An incident responder was able to recover a binary file through the ne...
Related Quizzes
View allCompTIA A Plus Certification Exam
CompTIA A Plus Exam Questions
CompTIA A Plus 1001 Exams Practice
CompTIA A Plus Practice Exam
CompTIA Network Plus Certification Exam Quiz
CompTIA Security Plus Exam Answers
Free CompTIA Security Plus Practice Test
CompTIA Security Plus Simulation Questions
CompTIA Security Plus 501 Practice Questions
CompTIA Security Plus Example Questions
- ✓ 500+ Practice Questions
- ✓ Detailed Explanations
- ✓ Progress Analytics
- ✓ Exam Simulations